As I understand it, when I print something from some device (say, my
Debian laptop), the device establishes a TCP/IP connection with the
printer to do the printing. In my (typical) setup, at the link level,
the device connects to the AP / switch / router wirelessly (via WPA2),
and so does the printer. Assuming the device and router are both
patched, the link between the device and the router is secure, but the
link between the router and printer is not, so any data I send between
the device and the printer will be secure as it traverses the first
link, but not the second. As I understand things, patching the router
doesn't really help secure the link between it and vulnerable devices
like the printer. Henrique recently noted that there is a setting
available on new OpenWRT and LEDE builds that can help, but it's
apparently not yet included in any release yet:



